Operating System - HP-UX
1846733 Members
4191 Online
110256 Solutions
New Discussion

Re: HIDS cannot save timetable

 
Elena Leontieva
Esteemed Contributor

HIDS cannot save timetable

Hi,

I have HPUX-HIDS E.04.01.23 HP-UX Host IDS E.04.01 installed on HP-UX 11.23.
I chose the schedule to run on Monday-Friday and save it. When I close/open the Schedule Manager my timetable looks OK.
But if I exit the System Manager and start it again, only Monday is highlighted in a timetable for this schedule.
What am I missing?

Thank you,
Elena.
3 REPLIES 3
Pierre Pasturel
Respected Contributor

Re: HIDS cannot save timetable

Hi Elena -

I can not currently reproduce this problem. Did you make sure to select your Surveillance Schedule in the Schedule Manager as well as the Surveillance Group in the Time Table tab, both when you set the time table and also when you viewed it after restarting the System Manager?

If so, please list the contents of your schedule file:

% cat /etc/opt/ids/schedules/.txt

where is the name of the schedule in question. I would like to see if the STARTTIME and ENDTIME values correspond to what you are seeing in the Schedule Manager Time Table tab.

Pierre
Elena Leontieva
Esteemed Contributor

Re: HIDS cannot save timetable

Hi,

This is the content of the file:
coci161(root):/etc/opt/ids/schedules > cat file-ww-creation.txt
SCHEDULE file-ww-creation
GLOBALS
aggregation | 1
rt_alerts | 0
aggr_tuples | ^/usr/lbin/swagent$ , 28800
suppression | 1
suppression_report | 1
suppression_interval | 6h
suppression_count | 100
suppression_targets_to_ignore | ^/etc/passwd$ | ^/etc/group$ | ^/stand/vmunix$ | ^/stand/system$ | ^/\.rhosts$ | ^/etc/inetd\.conf$
ENDGLOBALS
GROUPPERIOD
NAME FileModificationGroup
GMT 0
STARTTIME 9:00:1
ENDTIME 9:59:1
GROUP FileModificationGroup
ENDGROUP
ENDGROUPPERIOD
GROUPPERIOD
NAME FileModificationGroup
GMT 0
STARTTIME 9:00:2
ENDTIME 9:59:2
GROUP FileModificationGroup
ENDGROUP
ENDGROUPPERIOD
GROUPPERIOD
NAME FileModificationGroup
GMT 0
STARTTIME 9:00:3
ENDTIME 9:59:3
GROUP FileModificationGroup
ENDGROUP
ENDGROUPPERIOD
GROUPPERIOD
NAME FileModificationGroup
GMT 0
STARTTIME 9:00:4
ENDTIME 9:59:4
GROUP FileModificationGroup
ENDGROUP
ENDGROUPPERIOD
GROUPPERIOD
NAME FileModificationGroup
GMT 0
STARTTIME 9:00:5
ENDTIME 9:59:5
GROUP FileModificationGroup
ENDGROUP
ENDGROUPPERIOD
ENDSCHEDULE
coci161(root):/etc/opt/ids/schedules >

Thank you.
Pierre Pasturel
Respected Contributor

Re: HIDS cannot save timetable

Your schedule shows that the FileModificationGroup is scheduled to run Monday thru Friday between 9 and 10 am. See http://docs.hp.com/en/5992-2108/apes05.html for a description of the STARTTIME/ENDTIME syntax (HH:MM:D).

My guess is that you have some other schedule with a group that is scheduled to run on Monday only and that you have that other schedule and group selected (highlighted) when viewing the time table. Make sure you have selected "file-ww-creation" schedule in the Schedule list and the "FileModificationGroup" in the time table tab.

Pierre